Bill

Bill > SB1421


TN SB1421

TN SB1421
AN ACT to amend Tennessee Code Annotated, Title 20; Title 29 and Title 47, Chapter 18, relative to data security.


summary

Introduced
02/06/2025
In Committee
Crossed Over
Passed
Dead

Introduced Session

114th General Assembly

Bill Summary

As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.

AI Summary

This bill establishes a new legal framework for data security in Tennessee that provides businesses with an affirmative defense against data breach lawsuits if they maintain a robust cybersecurity program. Specifically, the bill defines key terms like "data breach," "personal information," and "covered entity," and requires businesses to create and maintain a written cybersecurity program with administrative, technical, operational, and physical safeguards. The program must protect sensitive information, continuously evaluate potential security threats, and include employee training with a designated security officer. To qualify for the affirmative defense, businesses must demonstrate that their cybersecurity program reasonably conforms to recognized industry frameworks, such as NIST standards, HIPAA security requirements, or Payment Card Industry standards. Importantly, the bill does not create a private right of action, meaning individuals cannot directly sue under this law, but it provides a legal shield for businesses that can prove they took comprehensive, proactive steps to protect sensitive data. The law will take effect on July 1, 2025, giving businesses time to implement the required cybersecurity measures.

Committee Categories

Justice

Sponsors (1)

Last Action

Assigned to General Subcommittee of Senate Judiciary Committee (on 03/09/2026)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...